Governing What We Don't Fully Understand: AI's New Demands on Directors and Owners
Company owners and board directors are increasingly responsible for AI-driven outcomes they did not design, may not fully understand, and in some cases do not even know are occurring. What makes this particularly challenging is that these outcomes are not static. They are continuously evolving, and the risks they generate do not wait patiently for the next quarterly board meeting.
This is not a technology problem. It is a governance problem - and it is arriving faster than most boards are prepared for.
AI has become deeply embedded across industries. In manufacturing, robots and cobots operate around the clock with minimal human intervention. In healthcare, AI interprets medical imaging. In agriculture, sensors and algorithms manage irrigation and yield. In financial services, AI systems assess credit, flag fraud, and price risk. A wastewater treatment plant that once relied on a technician checking water quality once a day now uses automated sensors that monitor and adjust continuously, day and night, regardless of who is on shift. The technology has moved well ahead of the governance frameworks designed to oversee it.
So why should directors and owners be particularly concerned? Because AI is not simply a new and more powerful tool. It represents a fundamental shift in how decisions are made, how risks are generated, and how accountability must be assigned. There are four dimensions to this shift that every director and owner should understand.
Four Dimensions of the Shift
- From Human Decisions to Machine-Assisted Decisions: We are systematically moving from frameworks of human judgment to machine-assisted decision systems. In many contexts this has generated remarkable gains - faster production, safer working conditions, greater consistency and larger scale. But the shift also means that decisions once made by identifiable people, using traceable reasoning, are increasingly made by systems whose logic is neither obvious nor easily interrogated. The efficiency gains are real. But so are the governance implications.
- From Known Risks to Unknown Risks: As AI tools proliferate, decisions across a wide range of business functions (hiring, lending, pricing, promotions, customer service, etc) are being made by systems that we do not fully understand, generating risks that we do not fully understand, and in some cases producing harms that we do not yet know exist. A hiring algorithm that systematically puts certain applicants at a disadvantage, or a pricing model that inadvertently violates consumer protection law, may operate for months or even years before anyone asks the right question.
- From Periodic Oversight to Continuous Risk: The quarterly board meeting was designed for a world where risks accumulated slowly enough that a periodic review could keep pace. That world no longer exists. AI systems operate continuously, dynamically, and often invisibly. Risks emerge between meetings, compound without warning, and can scale rapidly before a board has had the opportunity to convene. Governance that is episodic is no longer adequate when the systems being governed never stop running.
- From Observable Processes to Opaque Systems: There was a time when a director could reasonably expect to understand the key processes driving the business - to observe them, measure them, and make informed decisions accordingly. An owner even more so! Today, many AI systems do not afford that transparency. Outputs are generated by models whose internal logic is difficult to inspect, whose training data may be unknown, and whose decision pathways cannot always be reconstructed. Directors and owners are, in a growing number of cases, losing command over the decisions being made in their name.
The Changed Risk Profile
If these four shifts are real (and the evidence suggests they are), then the fundamental risk profile of every company using AI has changed. This is true whether the company has a formal board with independent directors or is owner-led with governance concentrated in a single individual or family. The risks fall into two broad categories.
The first category is the set of risks that AI itself creates:
- Decision Opacity: When directors and owners do not know how a decision was made. When they cannot trace how an outcome was generated, they cannot meaningfully evaluate it, defend it, or correct it.
- Distributed AI Usage: Employees across organizations are independently adopting AI tools, often free and publicly available, outside any internal governance structure. An employee uploading confidential client data to a consumer-grade AI assistant or using an AI tool to generate marketing materials drawn from copyrighted sources, may create significant legal exposure without any director ever being aware it happened.
- Data Leakage and IP Risk: Without guardrails, proprietary information, trade secrets, and personal data can enter external AI models with no ability to retrieve or contain them.
- Model Drift: AI systems that performed well at deployment can degrade over time as the data they operate on changes, producing increasingly unreliable outputs without any visible signal that something has gone wrong.
The second category consists of risks that AI amplifies or accelerates:
- Regulatory and Legal Exposure: The EU AI Act now imposes detailed obligations on companies with European operations, and US frameworks are developing. Colorado has already enacted AI-specific consumer protection legislation, and federal proposals are currently in play. Copyright liability is a live issue: companies have faced suits from Getty Images, major publishers, and others over AI systems trained on or generating protected content.
- Reputational Risk: AI errors do not stay contained. They scale instantly, and the reputational damage from a discriminatory hiring decision or a misleading AI-generated customer communication can outpace any legal consequence.
The Governance Gap
Here is the central problem that all the above creates: boards and owners are still largely operating with governance structures designed for a different era, while the systems they are responsible for have moved on without them.
Most boards continue to function on a quarterly cadence, reviewing backward-looking reports that describe what has already happened. AI operates continuously, dynamically, and often invisibly. The result is a structural mismatch that no amount of diligence within the existing framework can fully resolve. Very simply, the speed at which AI-generated risks emerge, and compound far exceeds the speed at which traditional governance can detect and respond to them.
Consider a board where the chair of the risk committee raises AI as a potential competitive threat – for example, a new market entrant using AI to take market share, or an incumbent using it to drive down costs. That is a valuable and necessary conversation. But identifying AI as a competitive risk on a risk register is not the same as governing the AI systems already operating inside the company. The gap between "we discussed it" and "we are governing it" is where the exposure lives.
The evidence suggests this gap is widespread. A Deloitte survey of 100 private company leaders published in April 2026 found that while 70% of boards are proactively engaged on technology investment and 67% on cybersecurity, only 25% are proactive on the ethical use of technology and just 22% on oversight of leadership’s ability to execute AI transformation. More striking still, executives ranked legal and regulatory compliance and risk resilience as the areas where they expect the least impact from their AI investments – the exact areas where the consequences of getting it wrong are most serious.
This gap has direct and growing legal consequences for directors and owners. The Mobley v. Workday case, which achieved nationwide class action certification in May 2025, is instructive. The lawsuit proceeded against Workday not as a software vendor but as an agent of the companies using its AI-powered hiring screening tools - meaning the companies deploying that tool was exposed to discrimination liability for outcomes generated by a system they had purchased, not built, and may not have fully understood. The lesson for directors and owners is uncomfortable but clear: deploying an AI tool does not transfer the governance responsibility for what that tool does. Liability stays with the deployer.
Courts are also beginning to signal more broadly that passive oversight is insufficient. The Meta board’s experience with Cambridge Analytica - where directors faced claims that they ignored warning signs around data privacy, ultimately resulting in a court-approved $190 million settlement - established an early precedent that boards cannot simply wait for problems to surface. The governance implications of director liability in AI-related matters are examined in greater depth in a number of places, including "How AI Transparency Impacts Board Responsibilities," which we commend to readers of this piece.
Duty of care - the obligation to be informed, prepared, and reasonably diligent - now requires understanding systems that were not built by the people responsible for overseeing them and asking questions that many directors do not yet know how to formulate. "I did not know" is no longer a defensible position. For private company owners, the exposure is, in some ways, more acute. A family business owner or founder who serves as both executive and governance authority has no independent board to share accountability, no audit committee to which AI risk can be delegated, and often no structure at all for the kind of continuous monitoring that AI now demands. The governance gap is not just an institutional problem. For many private company owners, it is a personal one.
What Directors and Owners Must Do Now
The challenge of governing AI systems one does not fully understand is real, but it is not insurmountable. The starting point is accepting that the board's role is not to become technically proficient in AI. That is neither realistic nor necessary. The role of directors and owners is to ask the right questions and ensure that qualified people within the organization are providing credible answers. If that internal capability does not exist, then the organization should engage external expertise With that framing in mind, the following are immediate priorities.
- Know Where AI Is Operating in Your Company. Before any governance structure can be effective, directors and owners need a clear picture of where AI tools are being used. Not just the systems formally deployed by the company, but the tools employees are using independently. The three questions every board should be asking management are: (i) Where are we using AI? (ii) What decisions is it influencing? (iii) What could go wrong, and how would we know? If management cannot answer these questions clearly, that itself is material information.
- Establish an AI Policy and Guardrails. Every company using AI (which today means almost every company!) needs a policy that defines acceptable use, establishes what data employees may and may not introduce into external AI tools, and sets out the governance process for deploying AI in higher-risk functions. The absence of such a policy is not a neutral position. It is an unmanaged risk. A word on guardrails, since the term is increasingly used but rarely defined. Formally: AI guardrails are the policies, technical controls, and oversight processes that define the boundaries within which AI systems are permitted to operate - and that detect and correct deviations when those boundaries are crossed. More simply: think of AI guardrails as the combination of traffic laws, speed limits, and automatic braking systems for AI - rules that set the boundaries, and mechanisms that enforce them.
- Assign Board-Level Responsibility for AI Oversight. AI risk should not be everyone's responsibility in the abstract and no one's responsibility in practice. Whether it sits with an existing audit or risk committee, or warrants a dedicated technology committee, the board needs a defined home for AI oversight with an explicit mandate. Committee charters should be updated to reflect this.
- Require Regular AI Risk Reporting. Boards should require management to report on AI deployments, incidents, and risk mitigation on a regular basis - not annually, and not only when something goes wrong. This reporting should cover not just what AI systems are doing but how they are performing over time, since model drift can quietly degrade outcomes long after a system has been approved and forgotten.
- Build in Scenario Testing. One of the most effective tools available to boards that lack deep technical expertise is the scenario question: what happens if this system fails, produces a biased outcome, or is fed bad data? Requiring management to work through failure scenarios, and to present the results to the board, builds oversight capacity without requiring directors to understand the underlying technology.
- Shift from Backward-Looking to Forward-Looking Governance. The quarterly review of past performance remains necessary but is no longer sufficient. Boards need to develop the habit of asking not just what happened, but what is emerging - what AI-related risks are building, what regulatory changes are approaching, and what the company is doing to stay ahead of them. Governance that only looks backward will always be reacting to events rather than anticipating them.
- Address Director Education. Directors cannot ask the right questions about systems they know nothing about. A commitment to ongoing AI literacy - not technical mastery, but sufficient understanding to engage meaningfully with management - is now a basic element of director competence. This is particularly important for boards of private companies, where the breadth of director experience may be narrower and the resources for education more limited.
The Hard Truth
Directors and owners are now responsible for systems they did not build, may not fully understand, and cannot always directly observe. This is the defining governance challenge of the current moment, and it will intensify before it eases.
The instinct to delegate this entirely to management, or to treat it as a technology problem rather than a governance problem, is understandable - but it is no longer safe. The legal and reputational consequences of passive oversight are becoming clearer with each passing year, and courts and regulators are not waiting for governance frameworks to catch up.
None of this means that directors must become AI experts. It means they must become better governors of AI - curious, persistent, and willing to be uncomfortable asking questions about systems whose answers they cannot always fully evaluate. That is, in the end, what good governance has always required. AI has simply raised the stakes.
In Closing
AI is not a technology issue that happens to touch governance. It is a governance issue that happens to involve technology. The distinction matters, because it determines who is responsible and what the appropriate response looks like.
Boards and owners who understand this - who treat AI oversight as a continuous responsibility rather than a periodic agenda item, who ask hard questions rather than accepting reassuring ones, and who build the structures needed to monitor what they cannot directly see - will be better positioned for whatever comes next. Those who do not will find that the gap between what they were responsible for and what they understood was not a defense. It was the problem.
ABOUT THE AUTHOR
Ram Mahidhara is an experienced board director, senior executive, and Professor of Practice with more than 30 years of global leadership in infrastructure finance, corporate governance, sustainability, and risk oversight. His career spans multilateral development finance, private sector innovation, board leadership, and executive education across Asia, Africa, Latin America, and the United States. Ram holds a Ph.D. in Economics from the University of Texas at Austin. He is a Qualified Risk Director® and holds certifications in Risk Governance and Private Company Governance (DCRO Institute / Private Directors Association) and High Performing Boards (IMD, Lausanne).
